konfiguracja mikrotik

/interface bridge

add admin-mac=00:00:00:00:00:00 ageing-time=5m arp=proxy-arp auto-mac=yes \

    comment="" disabled=no forward-delay=15s l2mtu=2304 max-message-age=20s \

    mtu=1500 name=bridge1 priority=0x8000 protocol-mode=none \

    transmit-hold-count=6

/interface ethernet

set 0 arp=enabled auto-negotiation=yes comment="" disabled=no full-duplex=yes \

    l2mtu=1632 mac-address=00:0C:42:1C:E1:3B mtu=1500 name=ether1 speed=\

    100Mbps

set 1 arp=enabled auto-negotiation=yes comment="" disabled=no full-duplex=yes \

    l2mtu=1632 mac-address=00:0C:42:1C:E1:3C mtu=1500 name=ether2 speed=\

    100Mbps

set 2 arp=enabled auto-negotiation=yes comment="" disabled=no full-duplex=yes \

    l2mtu=1632 mac-address=00:0C:42:1C:E1:7F mtu=1500 name=ether3 speed=\

    100Mbps

/interface wireless security-profiles

set default authentication-types="" eap-methods=passthrough group-ciphers="" \

    group-key-update=5m interim-update=0s mode=none name=default \

    radius-eap-accounting=no radius-mac-accounting=no \

    radius-mac-authentication=no radius-mac-caching=disabled \

    radius-mac-format=XX:XX:XX:XX:XX:XX radius-mac-mode=as-username \

    static-algo-0=none static-algo-1=none static-algo-2=none static-algo-3=\

    none static-key-0="" static-key-1="" static-key-2="" static-key-3="" \

    static-sta-private-algo=none static-sta-private-key="" \

    static-transmit-key=key-0 supplicant-identity=MikroTik tls-certificate=\

    none tls-mode=no-certificates unicast-ciphers="" wpa-pre-shared-key="" \

    wpa2-pre-shared-key=""

/interface wireless

set 0 ack-timeout=dynamic adaptive-noise-immunity=none allow-sharedkey=no \

    antenna-gain=0 antenna-mode=ant-b area="" arp=enabled band=5ghz \

    basic-rates-a/g=6Mbps,9Mbps,12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps \

    basic-rates-b="" burst-time=disabled comment="" compression=no country=\

    poland default-ap-tx-limit=0 default-authentication=yes \

    default-client-tx-limit=0 default-forwarding=yes dfs-mode=none \

    disable-running-check=no disabled=no disconnect-timeout=3s \

    frame-lifetime=0 frequency=5240 frequency-mode=regulatory-domain \

    hide-ssid=no hw-retries=4 mac-address=00:0B:6B:84:B8:D6 \

    max-station-count=2007 mode=station mtu=1500 name="Link" \

    noise-floor-threshold=default on-fail-retry-time=100ms \

    periodic-calibration=default periodic-calibration-interval=60 \

    preamble-mode=both proprietary-extensions=post-2.9.25 radio-name=\

    000B6B84B8D6 rate-set=configured scan-list=default security-profile=\

    default ssid="LINK 2" station-bridge-clone-mac=00:00:00:00:00:00 \

    supported-rates-a/g=6Mbps,9Mbps,12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps \

    supported-rates-b="" tx-power-mode=default update-stats-interval=disabled \

    wds-cost-range=50-150 wds-default-bridge=bridge1 wds-default-cost=100 \

    wds-ignore-ssid=no wds-mode=dynamic wmm-support=disabled

set 1 ack-timeout=dynamic adaptive-noise-immunity=none allow-sharedkey=no \

    antenna-gain=0 antenna-mode=ant-a area="" arp=enabled band=2.4ghz-b \

    basic-rates-a/g=6Mbps basic-rates-b=1Mbps burst-time=disabled comment="" \

    compression=no country=no_country_set default-ap-tx-limit=0 \

    default-authentication=yes default-client-tx-limit=0 default-forwarding=\

    yes dfs-mode=none disable-running-check=no disabled=no \

    disconnect-timeout=3s frame-lifetime=0 frequency=2412 frequency-mode=\

    manual-txpower hide-ssid=no hw-retries=4 mac-address=00:60:B3:0C:2A:82 \

    max-station-count=2007 mode=ap-bridge mtu=1500 name=Siec4 \

    noise-floor-threshold=default on-fail-retry-time=100ms \

    periodic-calibration=default periodic-calibration-interval=60 \

    preamble-mode=both proprietary-extensions=post-2.9.25 radio-name=\

    0060B30C2A82 rate-set=default scan-list=default security-profile=default \

    ssid="Siec 4 - zadzwon 9878723" station-bridge-clone-mac=\

    00:00:00:00:00:00 supported-rates-a/g=\

    6Mbps,9Mbps,12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps supported-rates-b=\

    1Mbps,2Mbps,5.5Mbps,11Mbps tx-power-mode=default update-stats-interval=\

    disabled wds-cost-range=50-150 wds-default-bridge=none wds-default-cost=\

    100 wds-ignore-ssid=no wds-mode=disabled wmm-support=disabled

/interface wireless manual-tx-power-table

set "Link" comment="" manual-tx-powers="1Mbps:17,2Mbps:17,5.5Mbps:17,11Mbps\

    :17,6Mbps:17,9Mbps:17,12Mbps:17,18Mbps:17,24Mbps:17,36Mbps:17,48Mbps:17,54\

    Mbps:17,HT20-1:0,HT20-2:0,HT20-3:0,HT20-4:0,HT20-5:0,HT20-6:0,HT20-7:0,HT2\

    0-8:0,HT40-1:0,HT40-2:0,HT40-3:0,HT40-4:0,HT40-5:0,HT40-6:0,HT40-7:0,HT40-\

    8:0"

set Siec4 comment="" manual-tx-powers="1Mbps:17,2Mbps:17,5.5Mbps:17,11Mbp\

    s:17,6Mbps:17,9Mbps:17,12Mbps:17,18Mbps:17,24Mbps:17,36Mbps:17,48Mbps:17,5\

    4Mbps:17,HT20-1:0,HT20-2:0,HT20-3:0,HT20-4:0,HT20-5:0,HT20-6:0,HT20-7:0,HT\

    20-8:0,HT40-1:0,HT40-2:0,HT40-3:0,HT40-4:0,HT40-5:0,HT40-6:0,HT40-7:0,HT40\

    -8:0"

/interface wireless nstreme

set "Link" comment="" disable-csma=no enable-nstreme=yes enable-polling=\

    yes framer-limit=3200 framer-policy=none

set Siec4 comment="" disable-csma=no enable-nstreme=no enable-polling=\

    yes framer-limit=3200 framer-policy=none

/ip hotspot profile

set default dns-name="" hotspot-address=0.0.0.0 html-directory=hotspot \

    http-cookie-lifetime=3d http-proxy=0.0.0.0:0 login-by=cookie,http-chap \

    name=default rate-limit="" smtp-server=0.0.0.0 split-user-domain=no \

    use-radius=no

/ip hotspot user profile

set default advertise=no idle-timeout=none keepalive-timeout=2m name=default \

    open-status-page=always shared-users=1 status-autorefresh=1m \

    transparent-proxy=yes

/ip ipsec proposal

set default auth-algorithms=sha1 disabled=no enc-algorithms=3des lifetime=30m \

    name=default pfs-group=modp1024

/ip pool

add name=dhcp_pool1 ranges=10.14.13.2-10.14.13.254

add name=dhcp_pool2 ranges=10.14.12.2-10.14.12.254

/ip dhcp-server

add address-pool=dhcp_pool1 authoritative=after-2sec-delay bootp-support=\

    static disabled=no interface=Siec4 lease-time=1d name=dhcp1

add address-pool=dhcp_pool2 authoritative=after-2sec-delay bootp-support=\

    static disabled=no interface=ether1 lease-time=1d name=dhcp2

/port

set 0 baud-rate=115200 data-bits=8 flow-control=none name=serial0 parity=none \

    stop-bits=1

/ppp profile

set default change-tcp-mss=yes comment="" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=default only-one=yes use-compression=no \

    use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=512k/1024k only-one=yes rate-limit=\

    512k/1024k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=512k/1032k only-one=yes rate-limit=\

    512k/1032k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=512k/1280k only-one=yes rate-limit=\

    512k/1280k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=256k/512k only-one=yes rate-limit=\

    256k/512k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=128k/400k only-one=yes rate-limit=\

    128k/400k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=1024k/2048k only-one=yes rate-limit=\

    1024k/2048k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=56k only-one=yes rate-limit=56k \

    use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=256k/768k only-one=yes rate-limit=\

    256k/768k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=1024k/6144k only-one=yes rate-limit=\

    1024k/6144k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=2048k/4092k only-one=yes rate-limit=\

    2048k/4092k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=2048k/2048k only-one=yes rate-limit=\

    2048k/2048k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=768k/1536k only-one=yes rate-limit=\

    768k/1536k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=1024k/1024k only-one=yes rate-limit=\

    1024k/1024k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=512k/512k only-one=yes rate-limit=\

    512k/512k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=128k/512k only-one=yes rate-limit=\

    128k/512k use-compression=no use-encryption=no use-vj-compression=no

add change-tcp-mss=yes comment="LMS Export" dns-server=78.98.45.12 \

    local-address=78.98.45.12 name=32k only-one=yes rate-limit=32k \

    use-compression=no use-encryption=no use-vj-compression=no

set default-encryption change-tcp-mss=default comment="" name=\

    default-encryption only-one=default use-compression=default \

    use-encryption=yes use-vj-compression=default

/queue type

set default kind=pfifo name=default pfifo-limit=50

set ethernet-default kind=pfifo name=ethernet-default pfifo-limit=50

set wireless-default kind=sfq name=wireless-default sfq-allot=1514 \

    sfq-perturb=5

set synchronous-default kind=red name=synchronous-default red-avg-packet=1000 \

    red-burst=20 red-limit=60 red-max-threshold=50 red-min-threshold=10

set hotspot-default kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=\

    5

set default-small kind=pfifo name=default-small pfifo-limit=10

/routing bgp instance

set default as=65530 client-to-client-reflection=yes comment="" disabled=no \

    ignore-as-path-len=no name=default out-filter="" redistribute-connected=\

    no redistribute-ospf=no redistribute-other-bgp=no redistribute-rip=no \

    redistribute-static=no router-id=0.0.0.0

/routing ospf area

set backbone area-id=0.0.0.0 authentication=none disabled=no name=backbone \

    type=default

/snmp

set contact="" enabled=yes engine-boots=80 engine-id="" location="" \

    time-window=0 trap-sink=0.0.0.0 trap-version=1

/snmp community

add address=78.98.67.0/22 authentication-password="" \

    authentication-protocol=MD5 encryption-password="" encryption-protocol=\

    DES name=public read-access=yes security=none write-access=no

/system logging action

set memory memory-lines=100 memory-stop-on-full=no name=memory target=memory

set disk disk-file-count=2 disk-file-name=log disk-lines-per-file=100 \

    disk-stop-on-full=no name=disk target=disk

set echo name=echo remember=yes target=echo

set remote bsd-syslog=no name=remote remote=78.98.67.4:514 src-address=\

    0.0.0.0 syslog-facility=daemon syslog-severity=auto target=remote

/user group

add comment="" name=read policy="local,telnet,ssh,reboot,read,test,winbox,pass\

    word,web,sniff,sensitive,!ftp,!write,!policy"

add comment="" name=write policy="local,telnet,ssh,reboot,read,write,test,winb\

    ox,password,web,sniff,sensitive,!ftp,!policy"

add comment="" name=full policy="local,telnet,ssh,ftp,reboot,read,write,policy\

    ,test,winbox,password,web,sniff,sensitive"

add comment="" name=Pracownik policy="local,reboot,read,test,winbox,password,s\

    ensitive,!telnet,!ssh,!ftp,!write,!policy,!web,!sniff"

/interface bridge port

add bridge=bridge1 comment="" disabled=no edge=auto external-fdb=auto \

    horizon=none interface="Link" path-cost=10 point-to-point=auto \

    priority=0x80

/interface bridge settings

set use-ip-firewall=no use-ip-firewall-for-pppoe=no use-ip-firewall-for-vlan=\

    no

/interface ethernet mirror

set

/interface l2tp-server server

set authentication=pap,chap,mschap1,mschap2 default-profile=\

    default-encryption enabled=no max-mru=1460 max-mtu=1460 mrru=disabled

/interface ovpn-server server

set auth=sha1,md5 certificate=none cipher=blowfish128,aes128 default-profile=\

    default enabled=no keepalive-timeout=60 mac-address=FE:B7:2F:D5:87:A7 \

    max-mtu=1500 mode=ip netmask=24 port=1194 require-client-certificate=no

/interface pppoe-server server

add authentication=pap,chap default-profile=default disabled=no interface=\

    bridge1 keepalive-timeout=10 max-mru=1480 max-mtu=1480 max-sessions=0 \

    mrru=disabled one-session-per-host=no service-name=Siec

add authentication=pap,chap default-profile=default disabled=no interface=\

    ether1 keepalive-timeout=10 max-mru=1480 max-mtu=1480 max-sessions=0 \

    mrru=disabled one-session-per-host=no service-name=Siec

add authentication=pap,chap default-profile=default disabled=no interface=\

    Siec4 keepalive-timeout=10 max-mru=1480 max-mtu=1480 max-sessions=0 \

    mrru=disabled one-session-per-host=no service-name=Siec

/interface pptp-server server

set authentication=mschap1,mschap2 default-profile=default-encryption \

    enabled=no keepalive-timeout=30 max-mru=1460 max-mtu=1460 mrru=disabled

/interface wireless align

set active-mode=yes audio-max=-20 audio-min=-100 audio-monitor=\

    00:00:00:00:00:00 filter-mac=00:00:00:00:00:00 frame-size=300 \

    frames-per-second=25 receive-all=no ssid-all=no

/interface wireless sniffer

set channel-time=200ms file-limit=10 file-name="" memory-limit=10 \

    multiple-channels=no only-headers=no receive-errors=no streaming-enabled=\

    no streaming-max-rate=0 streaming-server=0.0.0.0

/interface wireless snooper

set channel-time=200ms multiple-channels=yes receive-errors=no

/ip accounting

set account-local-traffic=no enabled=no threshold=256

/ip accounting web-access

set accessible-via-web=no address=0.0.0.0/0

/ip address

add address=10.14.12.1/24 broadcast=10.14.12.255 comment="" disabled=no \

    interface=Siec4 network=10.14.12.0

add address=10.14.13.1/24 broadcast=10.12.13.255 comment="" disabled=no \

    interface=ether1 network=10.12.13.0

add address=78.98.45.12/22 broadcast=78.98.67.255 comment="" disabled=no \

    interface=bridge1 network=78.98.67.0

/ip dhcp-server config

set store-leases-disk=5m

/ip dhcp-server network

add address=10.12.13.0/24 comment="" gateway=10.12.13.1

add address=10.12.14.0/24 comment="" gateway=10.12.14.1

add address=10.14.11.0/24 comment="" gateway=10.14.11.1

add address=10.14.12.0/24 comment="" gateway=10.14.12.1

add address=10.14.13.0/24 comment="" gateway=10.14.13.1

/ip dns

set allow-remote-requests=yes cache-max-ttl=1w cache-size=5048KiB \

    max-udp-packet-size=512 primary-dns=78.98.67.10 secondary-dns=\

    55.14.90.18

/ip firewall connection tracking

set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s \

    tcp-close-wait-timeout=10s tcp-established-timeout=1d \

    tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s \

    tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=no \

    tcp-time-wait-timeout=10s udp-stream-timeout=3m udp-timeout=10s

/ip firewall filter

add action=drop chain=forward comment="" disabled=no dst-address=!78.31.89.41 \

    src-address=10.14.12.0/24

add action=drop chain=forward comment="" disabled=no dst-address=!78.31.89.41 \

    src-address=10.14.13.0/24

add action=add-src-to-address-list address-list=spam address-list-timeout=1h \

    chain=forward comment="" connection-limit=3,32 disabled=no dst-port=25 \

    protocol=tcp src-address=18.12.10.0/23

add action=drop chain=forward comment="" disabled=no dst-port=25 protocol=tcp \

    src-address-list=spam

add action=drop chain=forward comment="" disabled=no dst-port=445 protocol=\

    udp

add action=drop chain=forward comment="" disabled=no dst-port=135-139 \

    protocol=tcp

add action=drop chain=forward comment="" disabled=no dst-port=135-139 \

    protocol=udp

add action=drop chain=forward comment="Filtr pakietow" connection-limit=70,32 \

    disabled=no dst-port=!80 in-interface="(unknown)" p2p=!all-p2p protocol=\

    tcp src-address=78.98.68.19

add action=accept chain=forward comment="Filtr pakietow" disabled=no \

    in-interface=bridge1 limit=75,80 src-address=78.98.68.19

add action=drop chain=forward comment="Filtr pakietow" disabled=no \

    in-interface=bridge1 src-address=78.98.68.19

add action=log chain=forward comment="" connection-state=new disabled=yes \

    log-prefix=""

/ip firewall nat

add action=masquerade chain=srcnat comment="" disabled=no out-interface=\

    bridge1 src-address=18.12.10.0/23

add action=dst-nat chain=dstnat comment="Strona Informacyjna LAN" disabled=no \

    dst-address=78.98.67.3 dst-port=80 protocol=tcp src-address=\

    10.12.13.0/24 to-addresses=78.98.67.3 to-ports=8088

add action=dst-nat chain=dstnat comment="" disabled=no dst-address=\

    78.98.67.2 dst-port=80 protocol=tcp src-address=10.12.13.0/24 \

    to-addresses=78.98.67.2 to-ports=8088

add action=masquerade chain=srcnat comment="" disabled=no dst-address=\

    78.98.67.3 out-interface=bridge1 src-address=10.12.13.0/24

add action=masquerade chain=srcnat comment="" disabled=no dst-address=\

    78.98.67.2 out-interface=bridge1 src-address=10.12.13.0/24

add action=dst-nat chain=dstnat comment="Strona Informacyjna Siec" \

    disabled=no dst-address=78.98.67.3 dst-port=80 protocol=tcp \

    src-address=10.14.12.0/24 to-addresses=78.98.67.3 to-ports=8088

add action=dst-nat chain=dstnat comment="" disabled=no dst-address=\

    78.98.67.2 dst-port=80 protocol=tcp src-address=10.14.12.0/24 \

    to-addresses=78.98.67.2 to-ports=8088

add action=masquerade chain=srcnat comment="" disabled=no dst-address=\

    78.98.67.3 out-interface=bridge1 src-address=10.14.12.0/24

add action=masquerade chain=srcnat comment="" disabled=no dst-address=\

    78.98.67.2 out-interface=bridge1 src-address=10.14.12.0/24

/ip firewall service-port

set ftp disabled=no ports=21

set tftp disabled=no ports=69

set irc disabled=no ports=6667

set h323 disabled=no

set sip disabled=no ports=5060,5061

set pptp disabled=no

/ip hotspot service-port

set ftp disabled=no ports=21

/ip neighbor discovery

set bridge1 discover=yes

set ether1 discover=yes

set ether2 discover=yes

set ether3 discover=yes

set "Link" discover=no

set Siec4 discover=no

/ip proxy

set always-from-cache=no cache-administrator=webmaster cache-hit-dscp=4 \

    cache-on-disk=no enabled=no max-cache-size=none max-client-connections=\

    600 max-fresh-time=3d max-server-connections=600 parent-proxy=0.0.0.0 \

    parent-proxy-port=0 port=8080 serialize-connections=no src-address=\

    0.0.0.0

/ip route

add comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\

    78.98.67.1 scope=255 target-scope=10

/ip service

set telnet address=0.0.0.0/0 disabled=no port=4423

set ftp address=0.0.0.0/0 disabled=no port=4421

set www address=0.0.0.0/0 disabled=no port=4480

set ssh address=0.0.0.0/0 disabled=no port=4422

set www-ssl address=0.0.0.0/0 certificate=none disabled=yes port=443

set api address=0.0.0.0/0 disabled=yes port=8728

set winbox address=0.0.0.0/0 disabled=no port=8291

/ip socks

set connection-idle-timeout=2m enabled=no max-connections=200 port=1080

/ip traffic-flow

set active-flow-timeout=30m cache-entries=4k enabled=yes \

    inactive-flow-timeout=15s interfaces=all

/ip traffic-flow target

add address=78.98.67.2:12345 disabled=no v9-template-refresh=20 \

    v9-template-timeout=30m version=5

/ip upnp

set allow-disable-external-interface=yes enabled=no show-dummy-rule=yes

/ppp aaa

set accounting=yes interim-update=15m use-radius=yes

/ppp secret

add caller-id="" comment="" disabled=no limit-bytes-in=0 limit-bytes-out=0 \

    name="" password="" profile=default routes="" service=any

add caller-id="" comment="" disabled=no limit-bytes-in=0 limit-bytes-out=0 \

    local-address=78.98.45.12 name=idiot@net password=iksi \

    remote-address=78.98.68.33 routes="" service=pppoe


/queue interface

set bridge1 queue=default

set ether1 queue=ethernet-default

set ether2 queue=ethernet-default

set ether3 queue=ethernet-default

set "Link" queue=wireless-default

set Siec4 queue=wireless-default

/radius

add accounting-backup=no accounting-port=1813 address=78.98.67.3 \

    authentication-port=1812 called-id="" comment="" disabled=no domain="" \

    realm="" secret="cccp[=" service=ppp timeout=5s

/radius incoming

set accept=yes port=6787

/routing mme

set bidirectional-timeout=2 gateway-class=none gateway-keepalive=1m \

    gateway-selection=no-gateway origination-interval=5s preferred-gateway=\

    0.0.0.0 timeout=1m ttl=50

/routing ospf

set distribute-default=never metric-bgp=20 metric-connected=20 \

    metric-default=1 metric-rip=20 metric-static=20 mpls-te-area=unspecified \

    mpls-te-router-id=unspecified redistribute-bgp=no redistribute-connected=\

    no redistribute-rip=no redistribute-static=no router-id=0.0.0.0

/routing rip

set distribute-default=never garbage-timer=2m metric-bgp=1 metric-connected=1 \

    metric-default=1 metric-ospf=1 metric-static=1 redistribute-bgp=no \

    redistribute-connected=no redistribute-ospf=no redistribute-static=no \

    timeout-timer=3m update-timer=30s

/routing rip interface

add authentication=none authentication-key="" disabled=no in-prefix-list="" \

    interface=all key-chain="" out-prefix-list="" passive=no receive=v2 send=\

    v2

/store

add comment="" disabled=no disk=system name=web-proxy1 type=web-proxy

/system clock

set time-zone-name=Europe/Warsaw

/system clock manual

set dst-delta=+00:00 dst-end="jan/01/1970 00:00:00" dst-start=\

    "jan/01/1970 00:00:00" time-zone=+00:00

/system console

add disabled=no port=serial0 term=vt102

/system health

set fan-mode=auto use-fan=main

/system identity

set name=Zalew

/system logging

add action=memory disabled=no prefix="" topics=info

add action=memory disabled=no prefix="" topics=error

add action=memory disabled=no prefix="" topics=warning

add action=echo disabled=no prefix="" topics=critical

add action=remote disabled=no prefix="" topics=info

add action=remote disabled=no prefix="" topics=critical

/system note

set note="" show-at-login=yes

/system ntp client

set enabled=yes mode=unicast primary-ntp=78.98.67.10 secondary-ntp=0.0.0.0

/system routerboard settings

set baud-rate=115200 boot-delay=2s boot-device=nand-if-fail-then-ethernet \

    boot-protocol=bootp enable-jumper-reset=yes enter-setup-on=any-key \

    force-backup-booter=no

/system scheduler

add comment="" disabled=yes interval=4m59s name=brak-radiusa on-event=\

    brak-radiusa policy=read,write,test start-date=jan/01/1970 start-time=\

    00:00:00

add comment="" disabled=no interval=23h59m name=konta-ppp on-event=konta-ppp \

    policy=read,write,test start-date=jan/01/1970 start-time=00:00:00

add comment="" disabled=no interval=50s name=limit on-event=limit policy=\

    read,write,test start-date=jan/01/1970 start-time=00:00:00

/system script

add name=brak-radiusa policy=\

    ftp,reboot,read,write,policy,test,winbox,password source=":if ([/ping 86.7\

    .89.90 count=1]=1) do={:foreach i in=[/ppp secret find disabled=no comme\

    nt=\"LMS Export\"]  \\\r\

    \ndo={/ppp secret disable \$i}} else {:foreach j in=[/ppp secret find disa\

    bled=yes comment=\"LMS Export\"] do={/ppp secret enable \$j}}"

add name=konta-ppp policy=ftp,reboot,read,write,policy,test,winbox,password \

    source=":foreach i in=[/file find name=ppp-export.rsc] do={:if (\$i=:nothi\

    ng) do={:nothing} else {/import ppp-export.rsc; /file remove \$i}}"

add name=limit policy=ftp,reboot,read,write,policy,test,winbox,password \

    source=":foreach k in=[/ip firewall filter find invalid=yes comment=\"Filt\

    r pakietow\"] \\\r\

    \n                       do={/ip firewall filter remove \$k};\r\

    \n:foreach i in=[/interface find type=pppoe-in] do={:set login[/interface \

    get \$i name]; :foreach j in=[/ip address find interface=\$i] do={:set ipa\

    ddr[/ip address get \$j network]; :foreach k in=[/queue simple find interf\

    ace=\$login] do={:set lim [/queue simple get \$k max-limit]; \r\

    \n       :set slashpos [:pick [:find \$lim \"/\"]];\r\

    \n       :set down ([:pic \$lim [:tonum(([:tonum(\$slashpos)] +1))] 30] );\

    \r\

    \n \r\

    \n :if ([:len [/ip firewall filter find comment=\"Filtr pakietow\" src-add\

    ress=\$ipaddr]]>0) \\\r\

    \n                do={:nothing} \\\r\

    \n                     else={:if (\$down<=320000) do={ \\\r\

    \n/ip firewall filter add chain=forward src-address=\$ipaddr in-interface=\

    \$login protocol=tcp dst-port=!80 connection-limit=35,32 p2p=!all-p2p acti\

    on=drop comment=\"Filtr pakietow\"; \\\r\

    \nip firewall filter add chain=forward src-address=\$ipaddr limit=50,60 in\

    -interface=\$login action=accept comment=\"Filtr pakietow\";  \\\r\

    \nip firewall filter add chain=forward src-address=\$ipaddr in-interface=\

    \$login action=drop comment=\"Filtr pakietow\";} \\\r\

    \n                         else={:if (\$down>320000 && \$down<=700000) do=\

    {\\\r\

    \n/ip firewall filter add chain=forward src-address=\$ipaddr in-interface=\

    \$login protocol=tcp dst-port=!80 connection-limit=50,32 p2p=!all-p2p acti\

    on=drop comment=\"Filtr pakietow\"; \\\r\

    \n                      ip firewall filter add chain=forward src-address=\

    \$ipaddr limit=65,70 in-interface=\$login action=accept comment=\"Filtr pa\

    kietow\";  \\\r\

    \nip firewall filter add chain=forward src-address=\$ipaddr in-interface=\

    \$login action=drop comment=\"Filtr pakietow\";}\\\r\

    \n                                  else={:if (\$down>700000) do={\\\r\

    \n/ip firewall filter add chain=forward src-address=\$ipaddr in-interface=\

    \$login protocol=tcp dst-port=!80 connection-limit=70,32 p2p=!all-p2p acti\

    on=drop comment=\"Filtr pakietow\"; \\\r\

    \n                                               ip firewall filter add ch\

    ain=forward src-address=\$ipaddr limit=75,80 in-interface=\$login action=a\

    ccept comment=\"Filtr pakietow\";  \\\r\

    \nip firewall filter add chain=forward src-address=\$ipaddr in-interface=\

    \$login action=drop comment=\"Filtr pakietow\";} \\\r\

    \n                                                      }}}}}};\r\

    \n"

/system upgrade mirror

set check-interval=1d enabled=no primary-server=0.0.0.0 secondary-server=\

    0.0.0.0 user=""

/system watchdog

set auto-send-supout=no automatic-supout=yes no-ping-delay=5m watch-address=\

    none watchdog-timer=yes

/tool bandwidth-server

set allocate-udp-ports-from=2000 authenticate=yes enabled=yes max-sessions=10

/tool e-mail

set from=<> password="" server=0.0.0.0:25 username=""

/tool graphing

set page-refresh=300 store-every=5min

/tool graphing interface

add allow-address=0.0.0.0/0 disabled=no interface=all store-on-disk=no

/tool graphing queue

add allow-address=0.0.0.0/0 allow-target=yes disabled=no simple-queue=all \

    store-on-disk=no

/tool graphing resource

add allow-address=0.0.0.0/0 disabled=no store-on-disk=no

/tool mac-server

add disabled=no interface=all

/tool mac-server ping

set enabled=yes

/tool sms

set allowed-number="" channel=0 keep-max-sms=0 receive-enabled=no secret=""

/tool sniffer

set file-limit=10 file-name="" filter-address1=0.0.0.0/0:0-65535 \

    filter-address2=0.0.0.0/0:0-65535 filter-protocol=ip-only filter-stream=\

    yes interface=all memory-limit=10 only-headers=no streaming-enabled=no \

    streaming-server=0.0.0.0

/user aaa

set accounting=yes default-group=read interim-update=0s use-radius=yes


Wyszukiwarka

Podobne podstrony:
konfiguracja mikrotika
MikroTik Konfiguracja Nstreme Dual
MikroTik konfiguracja szyfrowania WEP WPA
Chemia wyklad I i II (konfiguracja wiÄ…zania Pauling hybrydyzacja wiazania pi i sigma)
MikroTik AP Setup
07 Konfiguracja
06 4 8 mikrotunelowanie
Cwiczenie 12 Konfigurowanie i testowanie VPN (PPTP)
Konfiguracja pamięci mikrokontrolera 8051 dla programów napisanych w języku C
1.1.6 Opis i konfiguracja zestawu protokołów TCPIP, 1.1 Nawiązywanie połączenia z Internetem
SK-cw3 2h Konfigurowanie sieci WLAN, Sieci Komputerowe
KONFIGURACJA KROTNICY SDH SPRAWOZDANIE
Konfiguracja napędów optycznych
KONFIGURACJA KROTNICY SDH SPRAWOZDANIE
DNS konfiguracja serwera
konfiguracja sieci rejestratory bcs (2)